ZeroHour

Vulnerabilities

3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-44312
+1 in the same advisory: …44310
An issue was discovered in Firmware Analysis and Comparison Tool v3.2.

An issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators could be targeted by a CSRF attack through visiting a crafted web page.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • firmware analysis and comparison tool project firmware analysis and comparison tool
CVE-2020-11499
Firmware Analysis and Comparison Tool (FACT) 3 has Stored XSS when updating analysis details via a localhost web request, as demonstrated by mishandling of the

Firmware Analysis and Comparison Tool (FACT) 3 has Stored XSS when updating analysis details via a localhost web request, as demonstrated by mishandling of the tags and version fields in helperFunctions/mongo_task_conversion.py.

NVD description · AI analysis pending
6.1<1% PoC ×2
  • firmware analysis and comparison tool project firmware analysis and comparison tool